Author Topic: AVAST not showing notification on detection of malicious sites  (Read 5837 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
AVAST not showing notification on detection of malicious sites
« on: February 22, 2017, 06:28:59 PM »
AVAST 2017 Web Shield don't show any popup or warning message if we visit a malicious page twice. For example suppose I am visiting microkool.com/Dropfile/index.php by mistake. This is a known phishing site and is in the database of every antivirus product including AVAST. Now if I visit the above mentioned website, AVAST immediately tells threat has been detected and the connection to that site is aborted. This is absolutely fine. However again if we visit that website or any other phishing site (that is in the database of AVAST), AVAST don't show any notification or warning. It only blocks the connection silently in the background giving the user an interpretation that the website is temporarily not available or there might be some problem with proxy or dns.

AVAST shows notification again only if computer is restarted.

This issue is there in AVAST 2016, 2017. Any idea regarding this? Did someone here else experienced this issue or its me only?  :-\

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #1 on: February 22, 2017, 06:29:57 PM »
To add here, Chrome extension of AVAST turns RED second time when we visit malicious site. But no proper notification message or popup is shown.

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: AVAST not showing notification on detection of malicious sites
« Reply #2 on: February 22, 2017, 11:15:16 PM »
Don't worry. Once is detected malware, connection is disconnected by default. And if is disconnected, malware can't visit your PC. You can change this in web shield options.
« Last Edit: February 22, 2017, 11:17:57 PM by TheOwner »

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #3 on: February 23, 2017, 07:12:48 PM »
Yes I know that it is disconnected. But AVAST should show a notification as well every time we visit any malicious site.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: AVAST not showing notification on detection of malicious sites
« Reply #4 on: February 23, 2017, 07:43:18 PM »
Yes I know that it is disconnected. But AVAST should show a notification as well every time we visit any malicious site.

An entry would/should be place in the WebShield report file, C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

I would also suggest that you change the default settings for the Web Shield - AvastUI > Components > Web Shield - customise > Actions and set the Primary option to Ask. This will throw up the interactive alert window, so you will get a notification of sorts immediately. Your only other option is Abort Connection, which will close that alert window.

That said when you visit a malicious site (if avast detects it) then it aborts the connection, so you may be left with a blank browser page.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #5 on: February 24, 2017, 06:47:19 PM »
I certainly understand your point. But what I am trying to say that AVAST always should display pop up. Now the case is once it has shown popup for one malicious site, it will not show any other popup if you visit that particular site again or any other malicious sites. It blocks the connection though giving users a wrong interpretation that there might be something wrong with proxy or DNS or website is temporarily not available. There is an option 'show notification when action is taken' and that said when this option is ticked or checked it show a message every time we visit malicious site and not once.


Yes I know that it is disconnected. But AVAST should show a notification as well every time we visit any malicious site.

An entry would/should be place in the WebShield report file, C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

I would also suggest that you change the default settings for the Web Shield - AvastUI > Components > Web Shield - customise > Actions and set the Primary option to Ask. This will throw up the interactive alert window, so you will get a notification of sorts immediately. Your only other option is Abort Connection, which will close that alert window.

That said when you visit a malicious site (if avast detects it) then it aborts the connection, so you may be left with a blank browser page.

Offline Jiří Šembera

  • Avast team
  • Jr. Member
  • *
  • Posts: 46
  • Developer/Malware Analyst, former VPS maintainer
Re: AVAST not showing notification on detection of malicious sites
« Reply #6 on: February 24, 2017, 07:09:52 PM »
Hi skanungo2007,

this is a design decision because there were cases, when tons of alerts were showing up, because a program was trying to access a blocked page over and over again which was a huge annoyance. So there is a timeout for the alert to show up again - but just for the one particular URL. When you access a differend malicious site, the pop-up shows as expected.

Jiri

I certainly understand your point. But what I am trying to say that AVAST always should display pop up. Now the case is once it has shown popup for one malicious site, it will not show any other popup if you visit that particular site again or any other malicious sites. It blocks the connection though giving users a wrong interpretation that there might be something wrong with proxy or DNS or website is temporarily not available. There is an option 'show notification when action is taken' and that said when this option is ticked or checked it show a message every time we visit malicious site and not once.


Yes I know that it is disconnected. But AVAST should show a notification as well every time we visit any malicious site.

An entry would/should be place in the WebShield report file, C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

I would also suggest that you change the default settings for the Web Shield - AvastUI > Components > Web Shield - customise > Actions and set the Primary option to Ask. This will throw up the interactive alert window, so you will get a notification of sorts immediately. Your only other option is Abort Connection, which will close that alert window.

That said when you visit a malicious site (if avast detects it) then it aborts the connection, so you may be left with a blank browser page.

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: AVAST not showing notification on detection of malicious sites
« Reply #7 on: February 24, 2017, 07:15:35 PM »
I also raised this point with the Avast team but eventually agreed with them. This was mainly to stop spammed popups when malware was calling home every few seconds.

Response from Avast Team:
Quote
There is a 10 minute timer for which Avast remembers last 100 blocked URLs. For those URL the toaster does not show up again. It will show up once the 10 minutes pass or if you restart shields. Enabling the popup every time could in some cases lead to an endless sctream of popups that would flood the user. We do not want that. Also the logic when handling the last 100 blocked URLs within the 10 minute interval is different - the connection is immediately blocked instead of scanning its content. This is much more performance friendly. If we would scan the content every time, it could mean a severe performance hit to your system, hogging your CPU and memory.



Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: AVAST not showing notification on detection of malicious sites
« Reply #8 on: February 24, 2017, 07:26:39 PM »
I certainly understand your point. But what I am trying to say that AVAST always should display pop up. Now the case is once it has shown popup for one malicious site, it will not show any other popup if you visit that particular site again or any other malicious sites.

It blocks the connection though giving users a wrong interpretation that there might be something wrong with proxy or DNS or website is temporarily not available. There is an option 'show notification when action is taken' and that said when this option is ticked or checked it show a message every time we visit malicious site and not once.

Sorry I couldn't agree less, if they are going to show a popup (without the user changing the settings), showing that popup just once is totally crazy. If you go to a malicious site you get the popup, go back later or to another malicious site and not give an alert popup would give the user a False Negative. They believe the site/s are clear or the initial popup was an False Positive.

One of the most common popups on malicious sites is the URL:Mal popup and as Jiří Šembera mentioned, these usually come at regular intervals. They can also be an indication that you have an undetected or hidden malware file on your system that is trying to get out to connect to a malicious site.

EDIT: Typo.
« Last Edit: February 24, 2017, 07:34:44 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: AVAST not showing notification on detection of malicious sites
« Reply #9 on: February 24, 2017, 07:31:25 PM »
If you go to a malicious site you get the popup, go back later or to another malicious site and not give an alert popup would give the user a False Negative.

That's wrong. If you go to another malicious website, there will be an alert popup. Once you've received that alert for that website, you won't get a pop-up for 10 more mins on the websites you've already had the popup for unless you restart shields.

You can test with http://web-shield-test.avast.com/ and http://test-url-blocker.avast.com/

Edit: Added more info.
« Last Edit: February 24, 2017, 07:36:22 PM by Alikhan »
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #10 on: February 24, 2017, 08:40:01 PM »
Basically that don't happen. I have tested with different valid malicious site that are in the database of AVAST. Once a notification is shown for the first site, other sites gets blocked automatically without showing any notification. This is what really happens. If you want I can share some valid links (malicious) which are detected by AVAST but notifications are shown only once giving the user completely a false interpretation.

If you go to a malicious site you get the popup, go back later or to another malicious site and not give an alert popup would give the user a False Negative.

That's wrong. If you go to another malicious website, there will be an alert popup. Once you've received that alert for that website, you won't get a pop-up for 10 more mins on the websites you've already had the popup for unless you restart shields.

You can test with http://web-shield-test.avast.com/ and http://test-url-blocker.avast.com/

Edit: Added more info.

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #11 on: February 24, 2017, 08:43:47 PM »
If the case was really that, then it should be left to the user's discretion when and how to show alert messages. In fact when I have checked the option 'show notification window when action is taken' option, AVAST should show a pop up. Otherwise that can be considered as a bug. Now if too many alerts are generated in rare cases, there should be options like "Don't show notification for this event" and "restore hidden notification" by which user can enable or disable or better customize the way they want the alert.


Hi skanungo2007,

this is a design decision because there were cases, when tons of alerts were showing up, because a program was trying to access a blocked page over and over again which was a huge annoyance. So there is a timeout for the alert to show up again - but just for the one particular URL. When you access a differend malicious site, the pop-up shows as expected.

Jiri

I certainly understand your point. But what I am trying to say that AVAST always should display pop up. Now the case is once it has shown popup for one malicious site, it will not show any other popup if you visit that particular site again or any other malicious sites. It blocks the connection though giving users a wrong interpretation that there might be something wrong with proxy or DNS or website is temporarily not available. There is an option 'show notification when action is taken' and that said when this option is ticked or checked it show a message every time we visit malicious site and not once.


Yes I know that it is disconnected. But AVAST should show a notification as well every time we visit any malicious site.

An entry would/should be place in the WebShield report file, C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

I would also suggest that you change the default settings for the Web Shield - AvastUI > Components > Web Shield - customise > Actions and set the Primary option to Ask. This will throw up the interactive alert window, so you will get a notification of sorts immediately. Your only other option is Abort Connection, which will close that alert window.

That said when you visit a malicious site (if avast detects it) then it aborts the connection, so you may be left with a blank browser page.

REDACTED

  • Guest
Re: AVAST not showing notification on detection of malicious sites
« Reply #12 on: February 24, 2017, 08:47:30 PM »
I can share some valid malicious sites that are in the database of AVAST which I used for the purpose of testing to figure out the issue, but unfortunately AVAST shows blocked notification only for the first site that you visit. For others it is simply blocked. I don't know the timeout period as others mentioned. But what I did was to restart and check with some other URL and the same applies for that also.


If you go to a malicious site you get the popup, go back later or to another malicious site and not give an alert popup would give the user a False Negative.

That's wrong. If you go to another malicious website, there will be an alert popup. Once you've received that alert for that website, you won't get a pop-up for 10 more mins on the websites you've already had the popup for unless you restart shields.

You can test with http://web-shield-test.avast.com/ and http://test-url-blocker.avast.com/

Edit: Added more info.

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: AVAST not showing notification on detection of malicious sites
« Reply #13 on: February 24, 2017, 09:17:17 PM »
You can test with http://web-shield-test.avast.com/ and http://test-url-blocker.avast.com/.

Once you turn off shields and start them again, you'll get pop up again.

Regarding your malware samples, don't post them here. However, are you sure they're not from the same domain? A prime example would be AMTSO. Since they're coming from same domain after detection of of the first file, you wouldn't get the popups... same for EICAR files.
« Last Edit: February 24, 2017, 09:20:59 PM by Alikhan »
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

Offline midnight

  • Massive Poster
  • ****
  • Posts: 2473
Re: AVAST not showing notification on detection of malicious sites
« Reply #14 on: February 24, 2017, 11:16:48 PM »
@Alikhan,

I clicked on http://web-shield-test.avast.com/ and I got this pop-up.
.